Impact
The vulnerability is caused by Chrome’s ServiceWorker implementation not enforcing the page’s content security policy correctly. A crafted HTML page sent to a vulnerable browser can cause Chrome to ignore the CSP directives for that page, allowing attacker-provided content to be loaded without restriction.
Affected Systems
Google Chrome versions earlier than 147.0.7727.55 are affected. The flaw exists across all operating systems that Chrome supports, including Windows, macOS, and Linux.
Risk and Exploitability
The CVSS base score is 4.3, indicating low severeness, and the EPSS score is below 1 %, showing a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote: the attacker only needs to deliver a crafted HTML page that the user opens. Based on the description, it is inferred that the attacker can bypass the CSP to load scripts or resources that would normally be blocked, potentially leading to script execution within the page context.
OpenCVE Enrichment
Debian DSA